Privacy policy

How BugLoop handles personal data, for both our customers and the visitors who submit feedback through the widget. Last updated August 18, 2026.

This policy describes how the product actually behaves today. It has not yet been reviewed by legal counsel and will be finalized before general availability.

Who we are

BugLoop is operated by AI Venture Holdings LLC, a Utah limited liability company. For privacy questions, contact privacy@bugloop.ai.

Two kinds of people, two kinds of data

Customers are people who create a BugLoop account and install the widget. Visitors are people who submit feedback through a widget on a customer’s site. For visitor data, the customer is the controller and BugLoop is the processor.

What we collect from customers

  • Email address and authentication credentials, handled by Supabase Auth
  • Organization and project names you create
  • Integration configuration — repository or Jira project details, labels, assignees
  • Integration credentials, encrypted at rest and never readable through the data API
  • Server logs of requests to the application, retained by our hosting provider

What we collect from visitors

Only when a visitor acts, and only what that action produces:

  • The feedback type, severity, summary, and description they wrote, plus a design aspect or steps to reproduce where the customer’s form asks for them
  • Any custom field values the customer’s form asked for
  • A screenshot of the page, only where the customer has enabled screenshots and the visitor pressed the button and confirmed the preview
  • Whether the description was typed, dictated, or both — a one-word label, never any audio
  • Their email address, only if they chose to provide it
  • The page URL and page title they submitted from
  • The browser user agent string and viewport dimensions
  • A salted SHA-256 hash of their IP address, used only for rate limiting

Screenshots

Screenshots are optional for the customer and opt-in for the visitor. Nothing is captured unless the visitor presses “Attach a screenshot”, and the widget never requests a screen-sharing permission — it renders the page’s own content, so it cannot see another tab, another window, or anything else on the visitor’s device.

Before the image is rendered, the widget replaces the value of every input and textarea on the page with bullets and leaves any element the customer marked with data-bugloop-mask undrawn. Masking happens on the page, so no unmasked version of the image is created anywhere. The visitor then sees the image and can discard it; it is attached to the report only if they confirm it.

Images are held in a private storage bucket that no browser role can read or write. They are read only through time-limited signed links, one of which is embedded in the GitHub issue or uploaded to Jira as an attachment, and they are deleted when the report or the project is deleted.

Dictation

Where a customer has enabled dictation, the widget shows a microphone button that uses the browser’s own Web Speech API. In Chrome, that API transmits the captured audio to Google for transcription. That is a transfer to a third party, made by the visitor’s browser rather than by us, and it is the only such transfer the widget can cause.

Dictation is off unless the customer turns it on for a project, and the widget shows the visitor a one-line notice the first time the button is pressed. BugLoop never receives or stores the audio — only the text the browser returns, which the visitor can edit or delete before sending.

What we never collect

Nothing is collected passively. The widget performs no session recording, no heatmapping, and no tracking of clicks, scrolling, mouse movement, keystrokes outside its own form, or navigation between pages. It sets no cookies and writes nothing to localStorage or sessionStorage on a visitor’s browser. Raw IP addresses are never persisted. Apart from dictation, described above, the widget makes no third-party requests.

Cookies on this website

Signing in to the BugLoop dashboard sets a session cookie, which is strictly necessary for authentication. If Google Analytics is enabled on bugloop.ai, it starts in a denied consent state and stores nothing until you accept in the banner; your choice is recorded in localStorage on bugloop.ai. None of this applies to the embeddable widget, which sets no storage of any kind on customer sites.

Why we process it

  • To provide the service — routing feedback to the destination a customer configured
  • To protect the service — rate limiting and abuse prevention, using the IP hash
  • To communicate about a report, where a visitor asked to be told when it is resolved
  • To meet legal obligations

Where GDPR applies, our lawful bases are performance of a contract for service delivery and legitimate interests for abuse prevention. Visitor email is provided voluntarily by the visitor for the stated purpose.

Who it is shared with

Feedback content is transmitted to the issue tracker the customer configured — GitHub or Jira — because that is the function of the product. Screenshots travel the same way: as a signed link in the GitHub issue, or as a real attachment on the Jira ticket. Our infrastructure sub-processors are Vercel (hosting), Supabase (database, authentication and storage), and Resend (transactional email, when enabled). We do not sell personal data and we do not use it for advertising.

One transfer is not ours to make. Where a customer has enabled dictation, the visitor’s browser sends the captured audio to its own vendor’s speech service — Google, in Chrome — and returns text. We are not a party to that request and never hold the audio; it is described under Dictation above because it happens on a page our widget is on.

Retention

Feedback is kept until the customer deletes it or deletes the project it belongs to. Deleting a project deletes every report under it, including any email addresses, IP hashes, and stored screenshots. Rate-limit counters are pruned within 24 hours. Issues already created in a customer’s GitHub or Jira are outside our control and are governed by that customer’s own retention.

Your rights

Depending on where you live you may have rights of access, correction, deletion, portability, and objection. Customers can exercise most of these directly in the dashboard. Visitors should contact the site operator they submitted feedback to, since that operator controls the data; we will support them in responding. You may also write to privacy@bugloop.ai.

International transfers

Our infrastructure is currently hosted in the United States. If you are outside the US, your data will be processed there.

Children

BugLoop is a business tool and is not directed at children under 13. We do not knowingly collect their personal data.

Changes

Material changes will be announced to account holders before they take effect, and the date at the top of this page will be updated.